Linux Security
    Linux Security
    Linux Security

    Ubuntu: awstats vulnerabilities

    Date 16 Oct 2006
    5999
    Posted By LinuxSecurity Advisories
    awstats did not fully sanitize input, which was passed directly to the user's browser, allowing for an XSS attack. If a user was tricked into following a specially crafted awstats URL, the user's authentication information could be exposed for the domain where awstats was hosted. (CVE-2006-3681) awstats could display its installation path under certain conditions. However, this might only become a concern if awstats is installed into an user's home directory. (CVE-2006-3682)
    =========================================================== 
    Ubuntu Security Notice USN-360-1           October 10, 2006
    awstats vulnerabilities
    CVE-2006-3681, CVE-2006-3682
    ===========================================================
    
    A security issue affects the following Ubuntu releases:
    
    Ubuntu 5.04
    Ubuntu 5.10
    Ubuntu 6.06 LTS
    
    This advisory also applies to the corresponding versions of
    Kubuntu, Edubuntu, and Xubuntu.
    
    The problem can be corrected by upgrading your system to the
    following package versions:
    
    Ubuntu 5.04:
      awstats                                  6.3-1ubuntu0.4
    
    Ubuntu 5.10:
      awstats                                  6.4-1ubuntu1.3
    
    Ubuntu 6.06 LTS:
      awstats                                  6.5-1ubuntu1.2
    
    In general, a standard system upgrade is sufficient to effect the
    necessary changes.
    
    Details follow:
    
    awstats did not fully sanitize input, which was passed directly to the user's
    browser, allowing for an XSS attack.  If a user was tricked into following a
    specially crafted awstats URL, the user's authentication information could be
    exposed for the domain where awstats was hosted.  (CVE-2006-3681)
    
    awstats could display its installation path under certain conditions.
    However, this might only become a concern if awstats is installed into
    an user's home directory. (CVE-2006-3682)
    
    
    Updated packages for Ubuntu 5.04:
    
      Source archives:
    
        https://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.3-1ubuntu0.4.diff.gz
          Size/MD5:    27234 dfd36e862db2211270ccfcda1b9f4d3a
        https://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.3-1ubuntu0.4.dsc
          Size/MD5:      595 967d4b14c6a5bb7e2c69c3843d15eb0a
        https://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.3.orig.tar.gz
          Size/MD5:   938794 edb73007530a5800d53b9f1f90c88053
    
      Architecture independent packages:
    
        https://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.3-1ubuntu0.4_all.deb
          Size/MD5:   726704 52d471f9299e0bb5495c6e7db4fcc5fd
    
    Updated packages for Ubuntu 5.10:
    
      Source archives:
    
        https://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.4-1ubuntu1.3.diff.gz
          Size/MD5:    20294 23e7714e08623dd464a76b5d2618c9fa
        https://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.4-1ubuntu1.3.dsc
          Size/MD5:      595 e4ae507c9fc431a95b43fdc00f4a94e1
        https://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.4.orig.tar.gz
          Size/MD5:   918435 056e6fb0c7351b17fe5bbbe0aa1297b1
    
      Architecture independent packages:
    
        https://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.4-1ubuntu1.3_all.deb
          Size/MD5:   728744 ca061e390d9ed9056bb58e14bd8bbece
    
    Updated packages for Ubuntu 6.06 LTS:
    
      Source archives:
    
        https://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.5-1ubuntu1.2.diff.gz
          Size/MD5:    20075 5bdc75b3b0ae69ee240430b254b529aa
        https://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.5-1ubuntu1.2.dsc
          Size/MD5:      777 67d418d1283962b1955fffe465ed5d2e
        https://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.5.orig.tar.gz
          Size/MD5:  1051780 aef00b2ff5c5413bd2a868299cabd69a
    
      Architecture independent packages:
    
        https://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.5-1ubuntu1.2_all.deb
          Size/MD5:   853276 6213e0f258c78ce25b73a1f7a0152f4e
    
    
    

    Advisories

    LinuxSecurity Poll

    'Tis the season of giving! How have you given back to the open-source community?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/49-tis-the-season-of-giving-how-have-you-given-back-to-the-open-source-community?task=poll.vote&format=json
    49
    radio
    [{"id":"171","title":"I've contributed to the development of an open-source project.","votes":"8","type":"x","order":"1","pct":27.59,"resources":[]},{"id":"172","title":"I've reviewed open-source code for security bugs.","votes":"6","type":"x","order":"2","pct":20.69,"resources":[]},{"id":"173","title":"I've made a donation to an open-source project.","votes":"15","type":"x","order":"3","pct":51.72,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350

    Please vote first in order to view vote results.


    VIEW MORE POLLS

    bottom 200

    Please enable / Bitte aktiviere JavaScript!
    Veuillez activer / Por favor activa el Javascript![ ? ]

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.